Sub-technique of T1027 Obfuscated Files or Information.View on attack.mitre.org
Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection. Encrypting and/or encoding file content aims to conceal malicious artifacts within a file used in an intrusion. Many other techniques, such as Software Packing, Steganography, and Embedded Payloads, share this same broad objective. Encrypting and/or encoding files could lead to a lapse in detection of static signatures, only for this malicious content to be revealed (i.e., Deobfuscate/Decode Files or Information) at the time of execution/use.
This type of file obfuscation can be applied to many file artifacts present on victim hosts, such as malware log/configuration and payload files. Files can be encrypted with a hardcoded or user-supplied key, as well as otherwise obfuscated using standard encoding schemes such as Base64.
The entire content of a file may be obfuscated, or just specific functions or values (such as C2 addresses). Encryption and encoding may also be applied in redundant layers for additional protection.
For example, adversaries may abuse password-protected Word documents or self-extracting (SFX) archives as a method of encrypting/encoding a file such as a Phishing payload. These files typically function by attaching the intended archived content to a decompressor stub that is executed when the file is invoked (e.g., User Execution).
Adversaries may also abuse file-specific as well as custom encoding schemes. For example, Byte Order Mark (BOM) headers in text files may be abused to manipulate and obfuscate file content until Command and Scripting Interpreter execution.
Rules on DetectionCode tagged with T1027.013.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows Obfuscated Files or Information via RAR SFX | Anomaly | NULL | Sysmon EventID 11 |
| Used by | Procedure example |
|---|---|
| GroupAPT-C-36 | APT-C-36 has used encoded and obfuscated files, images, and executables. |
| GroupAPT18 | APT18 obfuscates strings in the payload. |
| GroupAPT19 | APT19 used Base64 to obfuscate payloads. |
| GroupAPT28 | APT28 encrypted a .dll payload using RTL and a custom encryption algorithm. APT28 has also obfuscated payloads with base64, XOR, and RC4. |
| GroupAPT32 | APT32 has performed code obfuscation, including encoding payloads using Base64 and using a framework called "Dont-Kill-My-Cat (DKMC). APT32 also encrypts the library used for network exfiltration with AES-256 in CBC mode in their macOS backdoor. |
| GroupAPT33 | APT33 has used base64 to encode payloads. |
| GroupAPT39 | APT39 has used malware to drop encrypted CAB files. |
| GroupBITTER | BITTER has used a RAR SFX dropper to deliver malware. |
| Used by | Procedure example |
|---|---|
| MalwareANELLDR | ANELLDR can update its encryption key to AES-256-CBC and re-encrypt its payload, overwriting the original payload file with the newly encrypted data. |
| MalwareAria-body | Aria-body has used an encrypted configuration file for its loader. |
| MalwareAshTag | The AshTag AshenOrchestrator component payload as been Base64 encoded and embedded with HTML content from the C2 server. |
| MalwareAstaroth | Astaroth has used an XOR-based algorithm to encrypt payloads twice with different keys. |
| MalwareAttor | Strings in Attor's components are encrypted with a XOR cipher, using a hardcoded key and the configuration data, log files and plugins are encrypted using a hybrid encryption scheme of Blowfish-OFB combined with RSA. |
| MalwareAuditCred | AuditCred encrypts the configuration. |
| MalwareAvenger | Avenger has the ability to XOR encrypt files to be sent to C2. |
| MalwareBazar | Bazar has used XOR, RSA2, and RC4 encrypted files. |
View all 195 software examples
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries utilized a Base64-encoded ZIP archive to prevent content analysis. |
| Campaign3CX Supply Chain Attack | During the 3CX Supply Chain Attack, AppleJeus encrypts its dynamic library files (.dll) using RC4, and when loaded only decrypts specific portions of the file using the key `3jB(2bsG#@c7`. |
| CampaignAPT41 DUST | APT41 DUST used encrypted payloads decrypted and executed in memory. |
| CampaignCutting Edge | During Cutting Edge, threat actors used a Base64-encoded Python script to write a patched version of the Ivanti Connect Secure `dsls` binary. |
| CampaignNight Dragon | During Night Dragon, threat actors used a DLL that included an XOR-encoded section. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group encrypted malware such as DRATzarus with XOR and DLL files with base64. |
| CampaignOperation Dust Storm | During Operation Dust Storm, the threat actors encoded some payloads with a single-byte XOR, both skipping the key itself and zeroing in an attempt to avoid exposing the key; other payloads were Base64-encoded. |
| CampaignOperation Honeybee | During Operation Honeybee, the threat actors used Base64 to encode files with a custom key. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.